Compliance Security Monitoring and Reporting Analyst

September 5

Apply Now
Logo of Finix

Finix

Payment Systems โ€ข Payment Facilitation โ€ข Risk and Undewriting โ€ข Payment Infrastructure โ€ข APIs

51 - 200 employees

Founded 2015

Description

โ€ข Identify and validate key controls from enterprise and functional risk assessments to mitigate risks. โ€ข Ensure annual updates to the Enterprise and functional risk assessments (Ops, Tech, People, Legal, IT) are completed and communicated to support SOC and InfoSec policy administration. โ€ข Manage key risk updates and remediation in our Drata GRC tool. โ€ข Develop and execute quarterly internal risk self-assessments and mini-audits of key controls, documenting required remediation to stay ahead of potential risks. โ€ข Oversee critical areas such as User Access reviews, Firewall rules reviews, Change Management, Vulnerability Management, Business Continuity/Disaster Recovery, and Employee training compliance. โ€ข Ensure compliance with PCI requirements for merchants, sub-merchants, and vendor PCI/SOC reports, and run OFAC sanctions screening during vendor approvals and contract renewals. โ€ข Conduct comprehensive compliance and risk reviews for all vendors and clients, ensuring they meet the corporate InfoSec program's requirements. โ€ข Operate the vendor re-review process, ensuring alignment with PCI, SOC, and Sponsor Bank requirements, and maintain thorough documentation for audits. โ€ข Gather evidence and documentation for external audits related to Compliance and InfoSec programs, including those by PCI QSA, SOC Audit firm, AML Independent Audit firm, Visa, Mastercard, American Express, Discover, and sponsor banks. โ€ข Track and document any required remediation from audit findings to ensure ongoing compliance.

Requirements

โ€ข Payments experience โ€ข An aptitude for digging deep into Information Security requirements โ€ข 3+ years of experience in PCI, SOC, security audits, AML audits or equivalent assessments (client-side, servicer, assessor, or industry consultant) โ€ข A talent for analyzing requirements of Information Security and Compliance frameworks, particularly as they relate to the payment industry, and crafting solutions for adherence โ€ข Knowledge of cloud computing and nuances of managing in an AWS/Microsoft/Google cloud vs. traditional on-premise data centers โ€ข Optional: Industry certifications (CRISC, CTPRP, SSCP, CISSP, CISA, CISM) that demonstrate your desire to be the best at what you do

Apply Now

Similar Jobs

Built byย Lior Neu-ner. I'd love to hear your feedback โ€” Get in touch via DM or lior@remoterocketship.com